Back to skill

Security audit

shell-review

Security checks across malware telemetry and agentic risk

Overview

This is a shell-script review skill with broad but purpose-aligned triggers and no hidden install, persistence, credential, or destructive behavior in the inspected artifacts.

Install this if you want structured shell-script review help. Be aware it may activate on broad shell or CI-related discussions, and review any suggested formatting or verification commands before applying changes to your repository.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest-style trigger list contains generic words like "shell," "bash," "posix," "scripting," "ci," and "hooks," plus a broad natural-language phrase about reviewing shell scripts. These terms overlap with common development discussion and the file does not provide exclusion conditions or tighter activation constraints, increasing the chance of accidental skill activation.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
70% confidence
Finding
Overly Broad Trigger: 'ci' is too short and may match unintended inputs

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
modules/structure-patterns.md:50